Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verification because Password::chap_verify() returns true when the supplied response does not match. Attackers who know a valid customer or PPPoE username can log in through MikroTik hotspot or PPPoE CHAP with any incorrect password to obtain network access and consume that customer's plan. | |
| Title | PHPNuxBill through 2025.3.20 CHAP Authentication Bypass via Password::chap_verify() | |
| Weaknesses | CWE-287 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T14:33:31.585Z
Reserved: 2026-10-09T13:44:40.883Z
Link: CVE-2026-108108
No data.
Status : Deferred
Published: 2026-10-09T15:17:11.887
Modified: 2026-10-09T16:45:01.980
Link: CVE-2026-108108
No data.
OpenCVE Enrichment
Updated: 2026-10-09T15:30:08Z
-
CWE-287
Improper Authentication